Vulnerabilities/

HackMD MCP Server has Server-Side Request Forgery (SSRF) vulnerability

Severity:
Medium

Description

A Server-Side Request Forgery (SSRF) vulnerability that affects all users running the HackMD MCP server in HTTP mode. Attackers could exploit this vulnerability by passing arbitrary hackmdApiUrl values through HTTP headers (Hackmd-Api-Url) or base64-encoded JSON query parameters.

Recommendation

Update the hackmd-mcp package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
hackmd-mcp
Anything's wrong? Let us know Last updated on September 15, 2025

This issue is available in SmartScanner Professional

See Pricing